I've been thinking about the mls cache entrys and inbound vs outbound accesslists. If i have an inbound acces list to an interfac the router inspects the packet before actually routing it. This improves router load when packets should be dropped. But an inbound access-list doesn't get mls cached and therefor the flow must pass up to the router before forwarding packets. So witch is the smartest way to do it? Letting the router drop packets before they get routed or populate the mls cache and drop packets on outbound? The router only process the route once since in's in the mls cache?
Am i getting this wrong?
/Andreas